Cleartext Password Exposure in IBM Tivoli Storage Products
CVE-2015-4949

Currently unrated

Summary

IBM Tivoli Storage Manager products risk exposing sensitive information due to the inclusion of cleartext passwords in exception messages. This vulnerability allows attackers with physical access to obtain passwords displayed on GUI pop-up windows, potentially compromising systems and sensitive data. It affects various IBM products designed for database management and email protection, necessitating caution and immediate updates to mitigate exploitation risks.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.